4 ms·
Can you provide more information regarding a system that can log these types of breaches (and all other activity, as required) and that would be deemed "safe" a
by cced 6y ago
Can you provide more information regarding a system that can log these types of breaches (and all other activity, as required) and that would be deemed "safe" and reliable post-breach? i.e.: A system that can provide logging and that can *assert* that all logs, even in the event of a breach, are asserted CIA?
- grit-t 6y agoAWS offers object locking, which is similar to a WORM drive (Write Once Read Many). This prevents logs from being deleted. The other approach is to ship logs to another AWS account. https://aws.amazon.com/blogs/storage/protecting-data-with-amazon-s3-object-lock/ https://aws.amazon.com/blogs/storage/protecting-data-with-am...
- neoncontrails 6y agoThanks. I was a bit puzzled earlier why AWS was so insistent about enabling object locking, my specific use case doesn't profit from remote versioning at all. But I can see how this would mitigate log integrity concerns. I'll definitely enable it for that.